<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:44:18 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-32895 — OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32895</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
Slack `member_*` and `message` subtype system events (`message_changed`, `message_deleted`, `thread_broadcast`) were not consistently enforcing sender authorization before enqueueing system events.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published version: `2026.2.25`
- Affected range: `&amp;lt;= 2026.2.25`
- Planned patched version: `2026.2.26` (pre-set for publish-readiness)&lt;/p&gt;
&lt;p&gt;### Technical Details
Slack system-event handlers in `src/slack/monitor/events/members.ts` and `src/slack/monitor/events/messages.ts` enqueued events after channel checks without shared sender authorization. Deployments relying on Slack DM allowlists (`dmPolicy` / `allowFrom`) or per-channel `users` allowlists could receive unauthorized system-event ingress from non-allowlisted senders.&lt;/p&gt;
&lt;p&gt;The fix routes those handlers through `authorizeAndResolveSlackSystemEventContext(...)` and fails closed when message subtype sender identity cannot be resolved.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `3d30ba18a2aba1e1b302e77ff33145c3b06c01c8`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to `&amp;gt;= 2026.2.26` so once npm `2026.2.26` is published, this advisory can be published without further field edits.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;### Summary
Slack `member_*` and `message` subtype system events (`message_changed`, `message_deleted`, `thread_broadcast`) were not consistently enforcing sender authorization before enqueueing system events.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published version: `2026.2.25`
- Affected range: `&amp;lt;= 2026.2.25`
- Planned patched version: `2026.2.26` (pre-set for publish-readiness)&lt;/p&gt;
&lt;p&gt;### Technical Details
Slack system-event handlers in `src/slack/monitor/events/members.ts` and `src/slack/monitor/events/messages.ts` enqueued events after channel checks without shared sender authorization. Deployments relying on Slack DM allowlists (`dmPolicy` / `allowFrom`) or per-channel `users` allowlists could receive unauthorized system-event ingress from non-allowlisted senders.&lt;/p&gt;
&lt;p&gt;The fix routes those handlers through `authorizeAndResolveSlackSystemEventContext(...)` and fails closed when message subtype sender identity cannot be resolved.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `3d30ba18a2aba1e1b302e77ff33145c3b06c01c8`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to `&amp;gt;= 2026.2.26` so once npm `2026.2.26` is published, this advisory can be published without further field edits.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32895</guid>
    </item>
    <item>
      <title>cnvd-2026-16384</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-16384</link>
      <description>cnvd-2026-16384</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-16384</guid>
    </item>
    <item>
      <title>EUVD-2026-329459</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329459</link>
      <description>EUVD-2026-329459</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329459</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32895</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32895</link>
      <description>&lt;p&gt;OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized events to be enqueued. Attackers can bypass Slack DM allowlists and per-channel user allowlists by sending system events from non-allowlisted senders through message_changed, message_deleted, and thread_broadcast events.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized events to be enqueued. Attackers can bypass Slack DM allowlists and per-channel user allowlists by sending system events from non-allowlisted senders through message_changed, message_deleted, and thread_broadcast events.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32895</guid>
    </item>
    <item>
      <title>GHSA-v8cg-4474-49v8 — OpenClaw: Slack system events bypass sender authorization in member and message subtype handlers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v8cg-4474-49v8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary
Slack `member_*` and `message` subtype system events (`message_changed`, `message_deleted`, `thread_broadcast`) were not consistently enforcing sender authorization before enqueueing system events.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published version: `2026.2.25`
- Affected range: `&amp;lt;= 2026.2.25`
- Planned patched version: `2026.2.26` (pre-set for publish-readiness)&lt;/p&gt;
&lt;p&gt;### Technical Details
Slack system-event handlers in `src/slack/monitor/events/members.ts` and `src/slack/monitor/events/messages.ts` enqueued events after channel checks without shared sender authorization. Deployments relying on Slack DM allowlists (`dmPolicy` / `allowFrom`) or per-channel `users` allowlists could receive unauthorized system-event ingress from non-allowlisted senders.&lt;/p&gt;
&lt;p&gt;The fix routes those handlers through `authorizeAndResolveSlackSystemEventContext(...)` and fails closed when message subtype sender identity cannot be resolved.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `3d30ba18a2aba1e1b302e77ff33145c3b06c01c8`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to `&amp;gt;= 2026.2.26` so once npm `2026.2.26` is published, this advisory can be published without further field edits.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;### Summary
Slack `member_*` and `message` subtype system events (`message_changed`, `message_deleted`, `thread_broadcast`) were not consistently enforcing sender authorization before enqueueing system events.&lt;/p&gt;
&lt;p&gt;### Affected Packages / Versions
- Package: `openclaw` (npm)
- Latest published version: `2026.2.25`
- Affected range: `&amp;lt;= 2026.2.25`
- Planned patched version: `2026.2.26` (pre-set for publish-readiness)&lt;/p&gt;
&lt;p&gt;### Technical Details
Slack system-event handlers in `src/slack/monitor/events/members.ts` and `src/slack/monitor/events/messages.ts` enqueued events after channel checks without shared sender authorization. Deployments relying on Slack DM allowlists (`dmPolicy` / `allowFrom`) or per-channel `users` allowlists could receive unauthorized system-event ingress from non-allowlisted senders.&lt;/p&gt;
&lt;p&gt;The fix routes those handlers through `authorizeAndResolveSlackSystemEventContext(...)` and fails closed when message subtype sender identity cannot be resolved.&lt;/p&gt;
&lt;p&gt;### Fix Commit(s)
- `3d30ba18a2aba1e1b302e77ff33145c3b06c01c8`&lt;/p&gt;
&lt;p&gt;### Release Process Note
`patched_versions` is pre-set to `&amp;gt;= 2026.2.26` so once npm `2026.2.26` is published, this advisory can be published without further field edits.&lt;/p&gt;
&lt;p&gt;Thanks @tdjackey for reporting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v8cg-4474-49v8</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0551 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0551</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder andere nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0551</guid>
    </item>
  </channel>
</rss>
